News: 1642711463

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Want to use Microsoft's Pluton chip? Up to you, say PC makers, it's opt-in for now

(2022/01/20)


PCs coming this year with Microsoft's integrated Pluton security chip won't be locked down to Windows 11, and users will have the option to install Linux and turn off the feature completely.

The first Windows 11 PCs with Pluton built-in were shown at CES earlier this month. Major PC chip makers, including Intel, AMD, and Qualcomm are embedding Pluton inside their microprocessors as a secure hardware layer.

But Microsoft's invasion at the hardware level has some users – especially in the open-source community – on high alert. The concern relates to the chip being a proprietary backdoor for Microsoft to take control of PCs and tying the hardware closely to Windows 11.

[1]

AMD integrated Microsoft's Pluton in Ryzen 6000 chips, which were introduced at CES earlier this month. AMD's goal is to bring better security to PCs, but users can disable Pluton.

[2]

[3]

"AMD respects user choice and, as is typical with many other security technologies, we provide the ability for a user to enable or disable Pluton based on their preferences in our reference BIOS," an AMD spokeswoman told The Register .

Pluton is a Windows security technology, but it does not restrict Linux installation, the spokeswoman said.

[4]

"AMD Ryzen 6000 Series processors support Linux. AMD has closely collaborated with Canonical (Ubuntu) and Red Hat to certify and optimize OEM designs with their operating systems," the spokeswoman said.

[5]Microsoft poaches Apple chip expert for custom silicon

[6]Windows giant seeks Pluton-ic relationship with chipmaker: AMD first out of the gates with Microsoft's security processor

[7]Windows 11 in detail: Incremental upgrade spoilt by onerous system requirements and usability mis-steps

[8]Microsoft brings Trusted Platform Module functionality directly to CPUs under securo-silicon architecture Pluton

Lenovo at CES announced new ThinkPads with AMD's Ryzen chips, but the laptops will ship without Pluton turned on.

"Pluton will be disabled by default on 2022 Lenovo ThinkPad platforms. Specifically the Z13, Z16, T14, T16, T14s, P16s and X13 using AMD 6000-series processors. Customers will have the ability to enable Pluton themselves," a Lenovo spokesperson told The Register .

An Intel spokesman told The Register that Alder Lake PCs will support Linux, but did not provide further details. He pointed out that the chip maker offered a Pluton-equivalent called Intel Platform Trust, which is a TPM 2.0, and helps protect against certain classes of physical attacks.

Pluton is designed for Windows PCs, and support for Linux "is currently an unsupported scenario," Microsoft spokesperson told The Register .

[9]

"Pluton is a hardware security technology that could be used by various OS components similar to how OS code can choose to use the TPM. Linux already has support for TPMs today, however Microsoft’s current focus is ensuring an optimal experience for Windows 11," Microsoft said in an email.

To be sure, Apple and Google have homegrown security processors in their own devices. Microsoft largely collaborates with chip makers to tune processors for Windows, but Pluton marks a [10]milestone in Microsoft's growing efforts to develop custom silicon.

It's up to PC makers to make this opt in or opt out

Pluton secures sensitive information like user credentials and encryption keys on integrated processor baked into the CPU die. Microsoft says that Pluton's proximity to the CPU mitigates systems from being exposed to chip-level security bugs like [11]Spectre and Meltdown , which prompted major tech companies, including [12]Microsoft , to rethink hardware systems and software.

Pluton for PCs evolved through security subsystems in the Xbox and the Azure Sphere IoT platform, which includes an Arm-based microcontroller and Linux OS. Microsoft has said Pluton provides "chip to cloud" security, with firmware updates coming through Windows Update.

"Pluton for Windows computers will be integrated with the Windows Update process in the same way that the Azure Sphere Security Service connects to IoT devices," Microsoft said in a [13]blog entry . The Azure Sphere Security Service uses a technique called remote attestation to authenticate a device and to ensure it has genuine software that is secure and trusted.

But the Xbox roots of Pluton has users [14]worried about it being some kind of DRM system, but Microsoft has said that Pluton is more of a building block to address the long-standing problem of securing PCs from bad actors.

PC makers can choose to ship computers with Pluton turned off, and the technology does not verify the signature of bootloaders, the Microsoft spokesman said. The security processor can be a Trusted Platform Module, or used in a non-TPM scenario, like to maintain system resiliency.

Microsoft has already [15]demonstrated that Pluton could be built into IoT systems based on Linux. The Azure Sphere IoT platform [16]Pluton security subsystem in the Arm-based MCU to identify and protect systems.

Microsoft told The Register it is committed to helping customers using Linux to secure environments, giving the example of a [17]proposal and shared code for a new Linux Security Module to help with the problem of authorizing code execution by policy. ®

Get our [18]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YenpmWbaDR4WV8zmOYtD1wAAAIA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YenpmWbaDR4WV8zmOYtD1wAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YenpmWbaDR4WV8zmOYtD1wAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YenpmWbaDR4WV8zmOYtD1wAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/01/13/microsoft_apple_chip_expert/

[6] https://www.theregister.com/2022/01/05/microsoft_pluton/

[7] https://www.theregister.com/2021/10/05/windows_11_in_detail/

[8] https://www.theregister.com/2020/11/17/microsoft_pluton_cpu_hardware_security/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YenpmWbaDR4WV8zmOYtD1wAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2022/01/13/microsoft_apple_chip_expert/

[11] https://www.theregister.com/2018/01/02/intel_cpu_design_flaw

[12] https://support.microsoft.com/en-us/topic/protect-your-windows-devices-against-speculative-execution-side-channel-attacks-a0b9f66c-f426-d854-fdbb-0e6beaeeee87

[13] https://www.microsoft.com/security/blog/2020/11/17/meet-the-microsoft-pluton-processor-the-security-chip-designed-for-the-future-of-windows-pcs/

[14] https://www.reddit.com/r/linux/comments/rwzoas/microsoft_to_introduce_chip_to_cloud_security/

[15] https://docs.microsoft.com/en-us/azure-sphere/product-overview/what-is-azure-sphere

[16] https://static.linaro.org/connect/san19/presentations/san19-210.pdf

[17] https://microsoft.github.io/ipe/

[18] https://whitepapers.theregister.com/



What's the real function?

The Empress

Copyright protection for Microsoft products? Forced subscriptions for everything? Engineered obsolescence?

Re: What's the real function?

Sandtitz

I can see lots of doubt, uncertainty and even fear in these comments. Not necessarily in that order.

There was a lot of ballyhoo, furore and hoopla back when Secure Boot came out. Or TPM before that. Did they really make Linux harder to install or use? No.

Re: What's the real function?

sten2012

It may be minor, but in all honesty it does, and short term (secure boot) the difference was significant.

Now most and probably all major distros can boot with secure boot enabled but for a long time they couldn't, then a few could and even now I couldn't comfortably say all can.

TPM, yeah, no.. I don't think that's ever impacted me.

hmmmmm

Boris the Cockroach

Quote

" Pluton is more of a building block to address the long-standing problem of securing PCs from bad actors."

Securing your PC from m$ should be the first step in that. especially since

Quote

"Microsoft has said Pluton provides "chip to cloud" security, with firmware updates coming through Windows Update."

Which will mean theres a way to run updates on the security thing from windows.......

Re: hmmmmm

ShadowSystems

Security software that can be modified while the OS is running? What could possibly go wrong?

*FacePalm*

Microsoft's integrated Pluton security chip

Howard Sway

Whassit stand for then?

Processor level user tax or notworking?

Prevent linux users thwarting our nonsense?

with firmware updates coming through Windows Update

heyrick

Yes, because that never goes wrong, does it?

So this thing can be quietly updated in the background with the OS running. Seems like their definition of trust is rather different to mine.

Re: with firmware updates coming through Windows Update

Sandtitz

"Yes, because that never goes wrong, does it?"

Which firmware updates through WU have gone wrong?

"So this thing can be quietly updated in the background with the OS running."

The other option would be to run broken firmware if a vulnerability or a show-stopper bug was found. The masses (which we both don't represent) never bother with any updates. They'd gladly use any unpatched device as long as it works.

Are they going to do the updates in secrecy you say?

Re: with firmware updates coming through Windows Update

sten2012

It's a root of trust. It just depends on all the stems/trunks/branches and leaves.

Note to self: must patent the "seed of trust" that comes before the root to keep ahead of this thing!

Mitigates against bugs like Spectre and Meltdown??

Detective Emil

How can Pluton, a hardware root of trust, protect against hardware shortcomings thar result in information leakage from branch prediction, or a race condition that discloses protected memory contents, either of which can be exploited from unprivileged code?

[Yes, I know: if Pluton is used to allow only approved and signed applications to run, as on iOS. But Microsoft has never managed to retrofit that model into Windows.]

DomDF

How long's left on the antitrust lawsuit timer? Surely it's about to go off.

cantankerous swineherd

meanwhile, in another part of the woods:

https://www.lightbluetouchpaper.org/2022/01/20/arm-releases-experimental-cheri-enabled-morello-board-as-part-of-187m-ukri-digital-security-by-design-programme/

Equal bytes for women.